Detections

Explore public detection logic contributed by the community across SIEM and rule languages.

39,169 detections

Detects file creation, modification, or renaming in System32 by TieringEngineService.exe or MsMpEng.exe within a short time frame.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects suspicious service creation or registry modifications involving WpnUserHost that do not reference System32.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects suspicious service creation or registry modifications related to wscl.exe that mimic persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects suspicious service creation or registry modifications related to wscl.exe that mimic persistence mechanisms.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects remote service creation consistent with PsExec-style lateral movement by correlating network logons (Type 3) with subsequent service installations.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects persistence activities initiated by Postgres-related processes or users involving scheduled tasks and system services.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects NTLM network logons (NtLmSsp) for accounts that may have been targets of certificate-based identity abuse (e.g., ESC1). Attackers often leverage this technique to extract NTLM hashes from PKINIT TGT PACs and subsequently utilize Pass-the-Hash for lateral movement within the network.
avatar
Lacey Cochrane@NullVectorX
avatar
XQL Threat Forge
1 month ago
204
Detects suspicious DNS queries to external service interaction domains often used for out-of-band interactions after successful RCE
avatar
SigmaHQ Detections@sigmaHQ
avatar
SigmaHQ
1 month ago
0018
This is something I have seen many times during my years working in cybersecurity: users download software with a filename they recognize and trust, but the file behind that name can be something completely different.

Monitoring the filename is not enough. Monitoring the hash is better, but legitimate software changes constantly: new version, new SHA256, another hash to validate and maintain. So I started thinking about how AI agents could help us here — not by deciding what is malicious, but by doing the repetitive work for us.

For this research, I built an AI-maintained baseline of legitimate software and used it from KQL to hunt two different scenarios:

🎯 Known filename + Unknown hash + Untrusted download source
avatar
Sergio Albea@Sergio_Albea
avatar
01 | 🇨🇭 Swiss Cyber Hunters
1 month ago
14126
Detects Adblock.dll used by Docro Hijacker to bypass Chrome Secure Preferences HMAC-SHA256 integrity checks and register infected browser UUID via vendralo[.]info
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
This rule detects the use of PowerShell to modify Microsoft Defender settings to disable real-time, behavior, and IOAV protection, while simultaneously adding a full-drive exclusion for the root directory (C:\). This behavior is characteristic of an adversary attempting to disable security monitoring to facilitate further malicious activity or avoid detection.
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects suspicious persistence mechanisms initiated by the 'wscl.exe' executable. The rule monitors for registry run key modifications, service installation via command-line arguments, and service creation events, specifically filtering for non-standard execution paths (outside of System32, SysWOW64, or Program Files).
avatar
Arnold Chan@slaz
Defender - KQL
29 days ago
000
Detects HVNC backdoor payload containing hardcoded AV/EDR process names combined with process enumeration APIs and a hex-suffixed mutex naming pattern, reducing false positives from generic AV name or API string matches alone
avatar
Arnold Chan@slaz
avatar
Midnight Slayer
29 days ago
000
Detects HVNC backdoor payload containing hardcoded AV/EDR process names combined with process enumeration APIs and a hex-suffixed mutex naming pattern, reducing false positives from generic AV name or API string matches alone
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects NSIS installer/archive contents bundling the specific unsigned/renamed UpdateAssistant.exe (aka AppUpdateHelper.exe) payload alongside its associated staged runtime DLLs and known malicious file paths/hashes used as cover noise for DLL sideloading staging
avatar
Arnold Chan@slaz
avatar
Detection & Hunting Community
29 days ago
000
Detects NSIS installer/archive contents bundling the specific unsigned/renamed UpdateAssistant.exe (aka AppUpdateHelper.exe) payload alongside its associated staged runtime DLLs and known malicious file paths/hashes used as cover noise for DLL sideloading staging
avatar
Arnold Chan@slaz
avatar
Detections.ai Community
29 days ago
000
Page 416 of 1866